Skip to content
This repository has been archived by the owner on Dec 19, 2024. It is now read-only.

SCP 008: Publish an invariant-centric threat model for OrbitDB #9

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

holmesworcester
Copy link

This proposal is to draft, approve, publish, and maintain an invariant-centric threat model for OrbitDB—that is, a list of security invariants and known weaknesses of OrbitDB that can be easily understood by all users and stakeholders, from teams building products on OrbitDB, to security auditors of those products, to end users of those products.

See Invariant-Centric Threat Modeling for a more thorough explanation of this methodology and its advantages.

A draft threat model is included, along with proposed steps for publishing, auditing, and maintenance.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant